4 ms·
Well that sucks. I guess in the long run we need a new engine and different approach. Someone should call the OpenBSD guys to come up with working ideas here.
by shevy-java 6mo ago
Well that sucks. I guess in the long run we need a new engine and different approach. Someone should call the OpenBSD guys to come up with working ideas here.
- giancarlostoro 6mo ago> Mozilla has quickly released the fix in Firefox 150 and ESR 140.10.0, and the patch is tracked in Mozilla Bug 2024220. Did you even read the article at all? Ah my children did bad in school, time to replace them with new children and a different spouse. This is what you're suggesting essentially. A browser is not just something you simply make out of thin air. There's decades of nuance to browser engines, and I'm only thinking of the HTML nuances, not the CSS or JS nuances.
- anthk 6mo agoGiven the dangers of JS and WASM they could just fork Netsurf and enhance the CSS3 support. If you are a journalist, running Tor with JS and tons of modern web tech enable makes you a bright white spot in a sea of darkness.
- fsflover 6mo agoHere you go: https://qubes-os.org https://qubes-os.org.
- Barbing 6mo ago>Why Qubes OS? >Physical isolation is a given safeguard that the digital world lacks … >In our digital lives, the situation is quite different: All of our activities typically happen on a single device. This causes us to worry about whether it’s safe to click on a link or install an app, since being hacked imperils our entire digital existence. >Qubes eliminates this concern by allowing us to divide a device into many compartments, much as we divide a physical building into many rooms. … Sold https://doc.qubes-os.org/en/latest/introduction/intro.html https://doc.qubes-os.org/en/latest/introduction/intro.html
- handedness 6mo agoQubes OS is a great solution for this threat model. By my (admittedly cursory) understanding of this attack, one would have to chain the attack to escalate to dom0 to get around it. Having said that, fsflover exhibits a poor grasp of how this stuff works and all should be aware that even in Qubes OS, one would need to spawn new disposable VMs for each identity; relying on the Tor Browser's new identity creation within the same disposable VM would be little different from running Tor Browser on a traditional OS.
- fsflover 6mo ago> one would need to spawn new disposable VMs for each identity This is by design how everyone should always be using Qubes OS for any task, according to its documentation and approach to security. > relying on the Tor Browser's new identity creation within the same disposable VM would be little different from running Tor Browser on a traditional OS Yes, if you use a single VM on Qubes OS for everything, then all security you get is from the OS running in this VM. This is not how you use Qubes, https://doc.qubes-os.org/en/r4.3/introduction/faq.html#how-does-qubes-os-provide-security https://doc.qubes-os.org/en/r4.3/introduction/faq.html#how-d... I run Qubes as a daily driver according to the docs, and my workflow was not vulnerable to the discussed attack.
- handedness 5mo agoAgain, this is some kind of technological No True Scotsman you keep doing. Yet again, please stop grossly misreading the comments of others. You consistently do it to numerous people here.
- fsflover 5mo agohttps://news.ycombinator.com/item?id=47878794 https://news.ycombinator.com/item?id=47878794
- handedness 6mo agoYou should note that improperly using Qubes OS, creating a New Identity inside of Tor Browser, even in a disposable Whonix workstation VM, would leave one vulnerable to this. A user would have to manually start a new disposable VM for each identity.
- fsflover 6mo agohttps://www.whonix.org/wiki/Multiple_Whonix-Workstation#Multiple_Whonix-Workstation_Rationale https://www.whonix.org/wiki/Multiple_Whonix-Workstation#Mult...